« Back to list

Craftcms

Craftcms Craft CMS: vulnerabilities and CVEs

Craftcms Craft CMS has 160 published vulnerabilities, 103 of them in the last 12 months. 13 are rated critical and 4 are listed by CISA as actively exploited.

CVEs160
Last 12 months103
Critical13
Actively exploited4

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-32432Critical (10)100%⚠ Active exploitationApr 25, 2025
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft…
CVE-2025-35939Medium (6.9)1.3%⚠ Active exploitationMay 7, 2025
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require…
CVE-2024-56145Critical (9.3)97%⚠ Active exploitationDec 18, 2024
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv`…
CVE-2025-23209High (8.1)22%⚠ Active exploitationJan 18, 2025
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-73858Medium (5.3)0.43%—Sep 23, 2026
Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be evaluated by the isolated Twig renderer when rendered…
CVE-2026-92593High (8.7)0.55%—Sep 16, 2026
Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a…
CVE-2026-92592High (8.7)0.65%—Sep 16, 2026
Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC…
CVE-2026-92591High (8.2)0.41%—Sep 16, 2026
Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed…
CVE-2026-92590Medium (5.1)0.24%—Sep 16, 2026
Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can…
CVE-2026-92589Medium (5.3)0.26%—Sep 16, 2026
Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but…
CVE-2026-79987High (8.7)0.65%—Sep 10, 2026
A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
CVE-2026-86732High (8.7)0.85%—Sep 8, 2026
Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter.…
CVE-2026-86731High (7.1)0.31%—Sep 8, 2026
Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does…
CVE-2026-86730High (8.7)0.71%—Sep 8, 2026
Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post…
CVE-2026-79991High (7.1)0.51%—Sep 2, 2026
Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering…
CVE-2026-79990High (8.7)0.45%—Sep 2, 2026
Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering…
CVE-2026-84802Medium (5.3)0.28%—Sep 2, 2026
Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit…
CVE-2026-84801High (8.7)0.44%—Sep 2, 2026
Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator…
CVE-2026-84800High (7.1)0.35%—Sep 2, 2026
Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target…
CVE-2026-84799Medium (5.3)0.28%—Sep 2, 2026
Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can…
CVE-2026-84798High (7.1)0.35%—Sep 2, 2026
Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled and runs…
CVE-2026-84797Medium (5.3)0.29%—Sep 2, 2026
Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts.…
CVE-2026-84796High (8.7)0.47%—Sep 2, 2026
Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to…
CVE-2026-84795Critical (9.2)0.51%—Sep 2, 2026
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit…
CVE-2026-84794High (7.1)0.35%—Sep 2, 2026
Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users'…
CVE-2026-84793Medium (4.8)0.25%—Sep 2, 2026
Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the…
CVE-2026-84792Medium (5.3)0.29%—Sep 2, 2026
Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers…
CVE-2026-79988High (8.7)0.45%—Aug 27, 2026
The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.
CVE-2026-78416High (8.7)1.0%—Aug 24, 2026
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in…
CVE-2026-52889Critical (9.8)1.3%—Aug 19, 2026
Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query…
CVE-2026-72787Medium (5.1)0.26%—Aug 12, 2026
Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can…
CVE-2026-72786High (7.1)0.46%—Aug 12, 2026
Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission…
CVE-2026-72785Critical (9.3)0.27%—Aug 11, 2026
Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify…
CVE-2026-72784Medium (6.9)0.24%—Aug 11, 2026
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches an attacker-supplied URL…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services20
  2. T1059 Command and Scripting Interpreter11
  3. T1190 Exploit Public-Facing Application10
  4. T1078 Valid Accounts4
  5. T1005 Data from Local System3
  6. T1565.001 Stored Data Manipulation3

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Craftcms